ADDED - Admin SEO page, robots/sitemap hardening and media/maintenance security fixes
SEO - New Settings > SEO admin page (seo_settings in app_config): indexing switch, Google/Bing verification, X handle, JSON-LD identity (Person/Organization, sameAs), per-locale keywords, readiness checklist and open links for sitemap.xml / robots.txt / manifest. - robots.txt is now dynamic: disallows admin, api, success and coming-soon paths; blocks everything while indexing is off or maintenance is on. - sitemap.xml carries hreflang alternates per URL, lists only categories with published projects, and is empty while hidden. - Metadata: robots + verification meta, og:locale in de_DE/en_US/ar_AR form, alternateLocale, twitter site/creator, project cover as OG image with article type, noindex on /success and /coming-soon. - JSON-LD: WebSite + publisher graph on all public pages, CreativeWork per project (view-mode independent). Security - Maintenance bypass now requires a correctly signed admin cookie; the middleware previously only checked the cookie existed. Token helpers moved to lib/admin-session-token.ts (shared by proxy.ts and lib/admin-auth.ts). - Media uploads: magic-byte validation against the declared type, SVG sanitization (script/handlers/foreignObject/javascript: rejected), upload folder sanitized, kind inferred from the real file. - Media route: fixed prefix-based path check that accepted sibling directories, unknown extensions return 404, nosniff header, CSP sandbox on SVG, gif content type added. - External media URLs: protocol-relative (//host) URLs rejected. Portfolio - Project and category slugs share /portfolio/[slug]; saving now rejects a slug already used on the other side instead of silently shadowing it. Tooling/docs - Lint: ignore scripts/legacy-prisma-seed.cjs, drop unused import. - New docs/SEO.md; FEATURES, ARCHITECTURE (Drizzle instead of Prisma), admin spec and CLAUDE.md updated. - Tests for all of the above (unit + integration); suite green.
This commit is contained in:
@@ -8,9 +8,11 @@ import { PageTransition } from "@/components/layout/page-transition";
|
||||
import { SiteDock } from "@/components/layout/site-dock";
|
||||
import { SiteFooter } from "@/components/layout/site-footer";
|
||||
import { ScrollSmootherProvider } from "@/components/scroll-smoother-provider";
|
||||
import { JsonLd } from "@/components/seo/json-ld";
|
||||
import { isSuperAdmin } from "@/lib/admin-auth";
|
||||
import { getMaintenanceMode, getSiteSettings } from "@/lib/app-config";
|
||||
import { getMaintenanceMode, getSeoSettings, getSiteSettings, getSiteSettingsMediaBindings } from "@/lib/app-config";
|
||||
import { getLocalizedPath, resolveLocale } from "@/lib/locale";
|
||||
import { buildSiteJsonLd } from "@/lib/metadata";
|
||||
|
||||
type SiteLayoutProps = {
|
||||
children: ReactNode;
|
||||
@@ -25,9 +27,11 @@ export const revalidate = 0;
|
||||
export default async function SiteLayout({ children, params }: SiteLayoutProps) {
|
||||
noStore();
|
||||
await params;
|
||||
const [maintenanceEnabled, siteSettings] = await Promise.all([
|
||||
const [maintenanceEnabled, siteSettings, seo, mediaBindings] = await Promise.all([
|
||||
getMaintenanceMode(),
|
||||
getSiteSettings(),
|
||||
getSeoSettings(),
|
||||
getSiteSettingsMediaBindings(),
|
||||
]);
|
||||
const localeKey = resolveLocale(await getLocale().catch(() => siteSettings.defaultLocale), siteSettings.defaultLocale);
|
||||
// Server-side decision only. The dock receives just this boolean and uses
|
||||
@@ -42,6 +46,7 @@ export default async function SiteLayout({ children, params }: SiteLayoutProps)
|
||||
|
||||
return (
|
||||
<>
|
||||
<JsonLd data={buildSiteJsonLd({ settings: siteSettings, seo, bindings: mediaBindings, locale: localeKey })} />
|
||||
<ScrollSmootherProvider />
|
||||
<SiteAmbientBackdrop />
|
||||
<SiteDock defaultLocale={siteSettings.defaultLocale} isSuperAdmin={authenticated} />
|
||||
|
||||
@@ -7,8 +7,9 @@ import { PageHero } from "@/components/layout/page-hero";
|
||||
import { PortfolioCategoryFilter } from "@/components/site/portfolio-category-filter";
|
||||
import { PortfolioProjectDetail } from "@/components/site/portfolio-project-detail";
|
||||
import { PortfolioProjectGrid } from "@/components/site/portfolio-project-grid";
|
||||
import { getSiteSettings } from "@/lib/app-config";
|
||||
import { buildLocalizedMetadata } from "@/lib/metadata";
|
||||
import { JsonLd } from "@/components/seo/json-ld";
|
||||
import { getSeoSettings, getSiteSettings } from "@/lib/app-config";
|
||||
import { buildLocalizedMetadata, buildProjectJsonLd } from "@/lib/metadata";
|
||||
import { resolveLocale } from "@/lib/locale";
|
||||
import {
|
||||
getActivePortfolioCategories,
|
||||
@@ -57,6 +58,9 @@ export async function generateMetadata({ params }: PortfolioSlugPageProps): Prom
|
||||
pathname: `/portfolio/${slug}`,
|
||||
title: getLocalizedValue(resolved.project.title, localeKey),
|
||||
description: getLocalizedValue(resolved.project.summary, localeKey),
|
||||
image: resolved.project.coverImagePath,
|
||||
type: "article",
|
||||
publishedTime: resolved.project.publishedAt,
|
||||
});
|
||||
}
|
||||
|
||||
@@ -108,13 +112,30 @@ export default async function PortfolioSlugPage({ params }: PortfolioSlugPagePro
|
||||
}
|
||||
|
||||
const { project: item } = resolved;
|
||||
const t = await getTranslations({ locale: localeKey, namespace: "portfolioDetail" });
|
||||
const [t, seo] = await Promise.all([
|
||||
getTranslations({ locale: localeKey, namespace: "portfolioDetail" }),
|
||||
getSeoSettings(),
|
||||
]);
|
||||
const title = getLocalizedValue(item.title, localeKey);
|
||||
const category = getLocalizedValue(item.category.name, localeKey);
|
||||
const summary = getLocalizedValue(item.summary, localeKey);
|
||||
const jsonLd = buildProjectJsonLd({
|
||||
settings: siteSettings,
|
||||
seo,
|
||||
locale: localeKey,
|
||||
pathname: `/portfolio/${slug}`,
|
||||
title,
|
||||
description: summary,
|
||||
image: item.coverImagePath,
|
||||
datePublished: item.publishedAt,
|
||||
genre: category,
|
||||
keywords: [getLocalizedValue(item.serviceLabel, localeKey), String(item.projectYear)].filter(Boolean),
|
||||
clientName: item.clientName,
|
||||
});
|
||||
|
||||
return (
|
||||
<>
|
||||
<JsonLd data={jsonLd} />
|
||||
<PageHero
|
||||
locale={localeKey}
|
||||
badge={category}
|
||||
|
||||
@@ -30,6 +30,7 @@ export async function generateMetadata({ params }: SuccessPageProps): Promise<Me
|
||||
pathname: "/success",
|
||||
title: t("title"),
|
||||
description: t("text"),
|
||||
noIndex: true,
|
||||
});
|
||||
}
|
||||
|
||||
|
||||
@@ -34,6 +34,7 @@ export async function generateMetadata({ params }: ComingSoonPageProps): Promise
|
||||
title: siteSettings.locales[localeKey].siteName,
|
||||
description: t("description"),
|
||||
applyTitleTemplate: false,
|
||||
noIndex: true,
|
||||
});
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user